<?xml version='1.0' encoding='utf-8'?>
<?xml-stylesheet type="text/xsl" href="/v2/static/oai2.xsl"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
  <responseDate>2026-10-06T05:20:19Z</responseDate>
  <request identifier="oai:figshare.com:article/34045599" metadataPrefix="oai_dc" verb="GetRecord">https://api.figshare.com/v2/oai</request>
  <GetRecord>
    <record>
      <header>
        <identifier>oai:figshare.com:article/34045599</identifier>
        <datestamp>2026-10-01T12:51:17Z</datestamp>
        <setSpec>category_29086</setSpec>
        <setSpec>category_29092</setSpec>
        <setSpec>item_type_12</setSpec>
        <setSpec>month_year_10_2026</setSpec>
      </header>
      <metadata>
        <oai_dc:dc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"  xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/" xmlns:dc="http://purl.org/dc/elements/1.1/" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd">
          <dc:title>CGROM Open Edition v2.0: Cyber Governance and Risk Operating Model</dc:title>
          <dc:creator>Thiago Oliveira Lima (25088590)</dc:creator>
          <dc:subject>Information security management</dc:subject>
          <dc:subject>Information systems education</dc:subject>
          <dc:subject>cybersecurity governance</dc:subject>
          <dc:subject>risk management</dc:subject>
          <dc:subject>operational resilience</dc:subject>
          <dc:subject>regulatory compliance</dc:subject>
          <dc:subject>NIST CSF 2.0</dc:subject>
          <dc:subject>third party risk</dc:subject>
          <dc:subject>incident governance</dc:subject>
          <dc:subject>maturity model</dc:subject>
          <dc:subject>DMAIC</dc:subject>
          <dc:subject>GRC</dc:subject>
          <dc:description>&lt;p dir="ltr"&gt;CGROM is an open operating model that connects day to day security work to risk decisions made and overseen by leadership in regulated organizations. Version 2.0 expands the Open Edition from six to ten governance mechanisms, adding policy architecture and exception management, control evidence and audit readiness, incident governance and materiality determination, and artificial intelligence governance. It adds a risk assessment method with published impact and likelihood anchors, a catalogue of twenty four key risk indicators and ten performance indicators with formulas and data sources, a section on third party and supply chain risk, an operational resilience method with a testing ladder and scenario library, a consolidated inventory of United States incident reporting obligations, an artificial intelligence governance overlay, four adoption paths and an artifact library. Regulatory crosswalks are extended from four to nineteen references. The self assessment retains the fifteen core statements of version 1.0 for comparability and adds a fifteen statement extended module.&lt;/p&gt;&lt;p dir="ltr"&gt;This edition builds on CGROM Open Edition version 1.0, published September 2026, &lt;a href="https://doi.org/10.6084/m9.figshare.33963217" target="_blank"&gt;https://doi.org/10.6084/m9.figshare.33963217&lt;/a&gt;. Version 1.0 remains available and citable. Version 2.0 adds material and does not withdraw or contradict any element of version 1.0, and is intended to be cited alongside it.&lt;/p&gt;</dc:description>
          <dc:date>2026-10-01T12:51:17Z</dc:date>
          <dc:type>Text</dc:type>
          <dc:type>Preprint</dc:type>
          <dc:identifier>10.6084/m9.figshare.34045599.v2</dc:identifier>
          <dc:relation>https://figshare.com/articles/preprint/CGROM_Open_Edition_v2_0_Cyber_Governance_and_Risk_Operating_Model/34045599</dc:relation>
          <dc:rights>CC BY 4.0</dc:rights>
        </oai_dc:dc>
      </metadata>
    </record>
  </GetRecord>
</OAI-PMH>
